# Internal Audits & Compliance Reviews | Document information | Value | |-----------------------|------| | Document type | Procedure instruction (VA-15) | | Scope | {{ISMS_SCOPE}} | | Organisation | {{ORG_NAME}} | | Process owner | {{ROLE_ISB}} | | Approved by | {{ROLE_MANAGEMENT}} | | Version | {{DOC_VERSION}} | | Date | {{DOC_DATE}} | | Status | {{DOC_STATUS}} | ## 1. Purpose This procedure governs the programme, planning, execution, reporting and measure tracking of internal audits as well as the independent review of the ISMS. It operationalises the associated policy ({{LINK:R03}}). ## 2. Scope Applies within the ISMS scope ({{ISMS_SCOPE_DESCRIPTION}}) for all policies, procedures and technical requirements within the scope. ## 3. Trigger Audit cycle (BL-GOV-01), material changes, request by management, prior findings. ## 4. Inputs - Audit programme register ({{LINK:REG-AUDIT-PLAN}}) - Controls / statement of applicability (SoA) - Previous audit reports & open measures ## 5. Process 1. Plan the **audit programme** in the **register ({{LINK:REG-AUDIT-PLAN}})** (scope, controls reviewed, dates, auditors) — cycle per **BL-GOV-01**. 2. Conduct the audit **independently** (auditor ≠ person responsible for the area reviewed). 3. Record findings/deviations and create them as measures in the ISMS tool ({{TOOL_NAME}}). 4. Report the audit report to {{ROLE_MANAGEMENT}} (input for the management review). 5. Track measures through to completion. 6. Independent review/assessment at least per **BL-GOV-01** or after fundamental changes. ## 6. RACI | # | Step | R (Execution) | A (Accountable) | C (Consulted) | I (Informed) | |---|---------|------------------|------------------|-----------------|----------------| | 1 | Plan the audit programme | {{ROLE_ISB}} | {{ROLE_ISB}} | Business units | - | | 2 | Conduct the audit | Auditor (independent) | {{ROLE_ISB}} | Area reviewed | - | | 3 | Record findings / create measures | {{ROLE_ISB}} | {{ROLE_ISB}} | Business unit | - | | 4 | Report to management | {{ROLE_ISB}} | {{ROLE_MANAGEMENT}} | - | {{ROLE_MANAGEMENT}} | | 5 | Track measures | {{ROLE_ISB}} | {{ROLE_ISB}} | Business unit | - | | 6 | Independent review | External/independent auditor | {{ROLE_MANAGEMENT}} | {{ROLE_ISB}} | - | ## 7. Result & evidence Audit reports, documented findings/measures and a maintained audit programme ({{LINK:REG-AUDIT-PLAN}}). Evidence is referenced in the central evidence register ({{LINK:NACHWEISREGISTER}}). ## 8. Key performance indicators (KPI) - Audit coverage of the controls - Open findings / on-time completion of measures - Share of audits completed on time ## 9. Related documents - Associated policy: {{LINK:R03}} - Register: {{LINK:REG-AUDIT-PLAN}} - Risk management procedure: {{LINK:VA-09}} - Technical security baseline: {{LINK:BASELINE}} - ISA mapping matrix: {{LINK:ISA_MAPPING}}